BlackKite: Home
Menu

PUBLISHED DATE: August 12, 2002CVE-2002-0421:
IIS 4.0 allows local...

CVSS:
5
EPSS:
2369.80%
Exploitability:
10
In KEV:
No
Description

IIS 4.0 allows local users to bypass the "User cannot change password" policy for Windows NT by directly calling .htr password changing programs in the /iisadmpwd directory, including (1) aexp2.htr, (2) aexp2b.htr, (3) aexp3.htr , or (4) aexp4.htr.

Products
Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2002-0421, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2002-0421 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?